Chapter 20 IPSec VPN
The ZyWALL and the remote IPSec router use DH
Figure 188 IKE SA: Main Negotiation Mode, Steps 3 - 4: DH Key Exchange
3
X 4 Y
DH
Authentication
Before the ZyWALL and remote IPSec router establish an IKE SA, they have to verify each other’s identity. This process is based on
In main mode, the ZyWALL and remote IPSec router authenticate each other in steps 5 and 6, as illustrated below. The identities are also encrypted using the encryption algorithm and encryption key the ZyWALL and remote IPSec router selected in previous steps.
Figure 189 IKE SA: Main Negotiation Mode, Steps 5 - 6: Authentication (continued)
Step 5:
ZyWALL identity, consisting of
-ID type
-content Step 6:
Remote IPSec router identity, consisting of
-ID type
-content
5
X 6 Y
You have to create (and distribute) a
| 307 |
ZyWALL 110/310/1100 Series User’s Guide | |
|
|